{"id":"CVE-2026-55380","aliases":["BIT-pillow-2026-55380","GHSA-phj9-mv4w-65pm","PYSEC-2026-2256"],"url":"https://o3.security/vulnerability/CVE-2026-55380","summary":"Pillow GdImageFile decompression bomb protection bypass","details":"Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.","published":"2026-07-06T18:50:14.789Z","modified":"2026-08-12T03:51:15.131477793Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.00418,"percentile":0.34557,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"pillow","fixedVersion":"12.3.0"}],"fix":{"url":"https://github.com/python-pillow/Pillow/commit/f39b0ae6624eb2d7c5c5d651d9bb5fdbd96a8675","label":"python-pillow/Pillow@f39b0ae"},"references":[{"type":"WEB","url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55380.json"},{"type":"ADVISORY","url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-phj9-mv4w-65pm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55380"},{"type":"FIX","url":"https://github.com/python-pillow/Pillow/commit/f39b0ae6624eb2d7c5c5d651d9bb5fdbd96a8675"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:15.131477793Z"}}